CVE-1999-1413
medium
📛 Threat Title
CVE-1999-1413
Description
Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (3)
- cve@mitre.org NVD Recent CVEs
- cve@mitre.org NVD Recent CVEs
-
NVD detail: CVE-1999-1413
NVD Recent CVEs
Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the set-gid group, which allows local users to overwrite or create files at higher privileges by causing a core dump, e.g. through dmesg.
Remediations (10)
-
web:cybersecuritynews.com
Google released a critical Chrome update fixing multiple high-risk vulnerabilities that could enable arbitrary code execution.
-
web:docs.tenable.com
Patch Management The primary objective of a patch management program is to prioritize vulnerabilities based on the full business context, including a comprehensive analysis of vulnerability characteristics and criticality rating for each asset. Not all vulnerabilities are created alike.
-
web:gemini.google.com
Meet Gemini, Google's AI assistant. Get help with writing, planning, brainstorming, and more. Experience the power of generative AI.
-
web:learn.microsoft.com
Use the DISM tool to fix problems that prevent Windows Update from installing successfully.
-
web:nvd.nist.gov
Vulnerabilities All vulnerabilities in the NVD have been assigned a CVE identifier and thus, abide by the definition below. CVE defines a vulnerability as: "A weakness in the computational logic (e.g., code) found in software and hardware components that, when exploited, results in a negative impact to confidentiality, integrity, or availability. Mitigation of the vulnerabilities in this ...
-
web:www.cisa.gov
If vulnerabilities cannot be remediated within the recommended timeframes, develop a remediation plan for action and coordination across the organization. The remediation plan should include: Vulnerability remediation constraints Interim mitigation actions to overcome constraints Final actions required to remediate vulnerability
-
web:www.cve.org
At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures
-
web:www.cyber.gov.au
If organisations choose to use products from vendors that don't provide security-only patches, they need to account for this in their patch management processes, as they may need to be ready to implement feature changes at short notice if security vulnerabilities are being exploited and require immediate patching.
-
web:www.esd.whs.mil
Ensure configuration, asset, remediation , and mitigation management supports vulnerability management within the DODIN in accordance with DoD Instruction (DoDI) 8510.01. Support all systems, subsystems, and system components owned by or operated on behalf of DoD with efficient vulnerability assessment techniques, procedures, and capabilities.
-
web:www.infosecinstitute.com
You can treat vulnerabilities in three ways: Remediate: Apply the patch or update to the software or system, so it's safe from exploitation. Mitigate: If remediation isn't an option because there is no patch or there are issues in updating the applications, then you move to mitigate.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.